Skip to content

Mozilla Firefox Security Technical Implementation Guide

Rules, Groups, and Values defined within the XCCDF Benchmark

  • SRG-APP-000141

    Group
  • Background submission of information to Mozilla must be disabled.

    Firefox by default sends information about Firefox to Mozilla servers. There should be no background submission of technical and other information from DoD computers to Mozilla with portions posted...
    Rule Medium Severity
  • SRG-APP-000266

    Group
  • SRG-APP-000175

    Group
  • Firefox must have the DOD root certificates installed.

    The DOD root certificates will ensure that the trust chain is established for server certificates issued from the DOD Certificate Authority (CA).
    Rule Medium Severity
  • SRG-APP-000326

    Group
  • Firefox must prevent the user from quickly deleting data.

    There should not be an option for a user to "forget" work they have done. This is required to meet non-repudiation controls.
    Rule Medium Severity
  • SRG-APP-000141

    Group
  • Firefox private browsing must be disabled.

    Private browsing allows the user to browse the internet without recording their browsing history/activity. From a forensics perspective, this is unacceptable. Best practice requires that browser hi...
    Rule Medium Severity
  • SRG-APP-000141

    Group

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules